8.7

CVSS4.0

CVE-2026-35029 - LiteLLM affected by privilege escalation via unrestricted proxy configuration endpoint

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environmen…

📅 Published: April 6, 2026, 4:35 p.m. 🔄 Last Modified: April 29, 2026, 8:16 p.m.

7.1

CVSS4.0

CVE-2026-34992 - Missing Encryption of Sensitive Data in antrea.io/antrea

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to 2.4.5 and 2.5.2, a missing encryption vulnerability affects inter-Node Pod traffic. In Antrea clusters configured for dual-stack networking with IPsec encryption enabled (trafficEncryptionMode: ipsec), Antrea fail…

📅 Published: April 6, 2026, 4:31 p.m. 🔄 Last Modified: April 27, 2026, 11:51 p.m.

6.9

CVSS4.0

CVE-2026-5669 - Cyber-III Student-Management-System Parameter login.php sql injection

A vulnerability has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This vulnerability affects unknown code of the file /login.php of the component Parameter Handler. Such manipulation of the argument Password leads to sql injection. It is possible …

📅 Published: April 6, 2026, 4:30 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

9.4

CVSS4.0

CVE-2026-34989 - CI4MS affected by Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalat…

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 31.0.0.0, the application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An att…

📅 Published: April 6, 2026, 4:25 p.m. 🔄 Last Modified: April 27, 2026, 11:41 p.m.

7.5

CVSS3.1

CVE-2026-34986 - Go JOSE affect by a panic in JWE decryption

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will pani…

📅 Published: April 6, 2026, 4:22 p.m. 🔄 Last Modified: May 4, 2026, 3:20 p.m.

5.8

CVSS3.1

CVE-2026-34981 - whisperX REST API: SSRF in download_from_url() — URL validation happens after HTTP request, extensi…

The whisperX API is a tool for enhancing and analyzing audio content. From 0.3.1 to 0.5.0, FileService.download_from_url() in app/services/file_service.py calls requests.get(url) with zero URL validation. The file extension check occurs AFTER the HTTP request is already made, and can be bypassed by…

📅 Published: April 6, 2026, 4:19 p.m. 🔄 Last Modified: April 27, 2026, 2:44 p.m.

9.3

CVSS4.0

CVE-2026-34977 - Aperi'Solve Affected by Unauthenticated RCE via JPSeek Analyzer Command

Aperi'Solve is an open-source steganalysis web platform. Prior to 3.2.1, when uploading a JPEG, a user can specify an optional password to accompany the JPEG. This password is then directly passed into an expect command, which is then subsequently passed into a bash -c command, without any form of …

📅 Published: April 6, 2026, 4:16 p.m. 🔄 Last Modified: April 22, 2026, 7:47 p.m.

4.8

CVSS4.0

CVE-2026-5668 - Cyber-III Student-Management-System add%20notice.php cross site scripting

A flaw has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affects an unknown part of the file /admin/Add%20notice/add%20notice.php. This manipulation of the argument $_SERVER['PHP_SELF'] causes cross site scripting. It is possible to initiate …

📅 Published: April 6, 2026, 4:15 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

10

CVSS3.1

CVE-2026-34976 - Dgraph Affected by Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authori…

Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from the authorization middleware config (admin.go), making it completely unauthenticated. Unlike the similar restore mutation which requires Guardian-of-Galaxy authentication, restor…

📅 Published: April 6, 2026, 4:12 p.m. 🔄 Last Modified: April 22, 2026, 7:51 p.m.

8.5

CVSS3.1

CVE-2026-34975 - Plunk has a CRLF Email Header Injection in raw MIME message construction allows authenticated API u…

Plunk is an open-source email platform built on top of AWS SES. Prior to 0.8.0, a CRLF header injection vulnerability was discovered in SESService.ts, where user-supplied values for from.name, subject, custom header keys/values, and attachment filenames were interpolated directly into raw MIME mess…

📅 Published: April 6, 2026, 4:10 p.m. 🔄 Last Modified: April 22, 2026, 7:58 p.m.
Total resulsts: 349182
Page 662 of 34,919
« previous page » next page
Filters